Back to Feed
Privacy FinesOct 9, 2026

Italian DPA fines BBVA EUR 5 508 000 for failing to respect a customer’s objection to direct marketing

Italian DPA fines BBVA EUR 5.5M for ignoring customer's direct marketing opt-out.

Summary

The Italian Data Protection Authority (DPA) has fined BBVA's Italian branch EUR 5,508,000 for failing to honor a customer's objection to direct marketing. Despite the customer exercising their right to opt-out via the bank's app and customer service, promotional notifications continued for seven months due to a technical failure. The DPA found BBVA infringed GDPR principles by not facilitating data subject rights and ordered the bank to implement corrective measures.

Full text

Italian DPA fines BBVA EUR 5 508 000 for failing to respect a customer’s objection to direct marketing National News 09 October 2026 it Background informationDate of final decision: 3 July 2026National caseController: Banco Bilbao Vizcaya Argentaria, S.A., Italian branch (BBVA)Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 12 (Transparent information, communication and modalities for the exercise of the rights of the data subject), Article 21 (Right to object), Article 24 (Responsibility of the controller)Decision: Administrative fine, Compliance orderWebsite topics: Basic principles, Data subjects rights, MarketingSummary of the DecisionOrigin of the case The Italian Data Protection Authority (DPA) investigated BBVA, a multinational Spanish banking group, following a complaint from a customer who continued to receive promotional communications through the bank’s mobile app despite having objected to direct marketing.The customer exercised his right to object through the settings provided in the BBVA app and subsequently reiterated his objection to the bank’s Customer Service. Nevertheless, promotional notifications continued for seven months, from October 2025 to May 2026.BBVA explained that the customer’s choice had been correctly recorded but that a technical failure prevented synchronisation between its internal systems and the Customer Relationship Management unit responsible for sending commercial communications.Key FindingsThe Italian DPA found that BBVA failed to give effect to the customer’s objection correctly and in a timely manner. During the relevant period, the customer received at least ten unsolicited commercial notifications.The DPA rejected BBVA’s argument that the customer should have used the dedicated email addresses indicated in its privacy policy. The customer had correctly exercised his right through the app and had also contacted Customer Service. Controllers must facilitate the exercise of data subject rights and cannot disregard a valid request merely because it was not submitted through a preferred channel.The DPA also found deficiencies in BBVA’s technical and organisational measures. In particular, Customer Service provided incorrect information by telling the customer that promotional pop-up notifications in the app could not be disabled, although BBVA subsequently demonstrated that they could be stopped.DecisionThe Italian DPA found infringements of Articles 5(1)(a), 12, 21 and 24 GDPR and imposed an administrative fine of EUR 5 508 000.The DPA ordered BBVA to adopt appropriate technical and organisational measures to facilitate the exercise of data subject rights and to ensure that requests are handled correctly and without undue delay. BBVA must also inform the DPA, within 30 days of notification of the decision, of the measures taken to comply with the order.When determining the fine, the DPA considered that the infringement concerned one data subject, lasted seven months and involved contact data for marketing purposes. It also considered BBVA’s remedial measures as a mitigating factor and a previous relevant infringement as an aggravating factor.For further information: Decision concerning Banco Bilbao Vizcaya Argentaria, S.A. (IT) Relevant topics Basic principles Data subject rights Marketing Latest news RSS Feed National News it Italian DPA fines Emirates EUR 180 000 for infringements concerning passengers’ health data09 October 2026 National News se Swedish DPA fines Miljödata i Karlskrona approximately EUR 160 000 for insufficient technical and organisational measures to ensure information security08 October 2026 National News nl Dutch DPA fines Uber EUR 824 990 000 for unlawful automated decision-making and insufficient information on profiling08 October 2026All news

Entities

BBVA (vendor)